Dealing With Insider Data Theft

To learn that your company's confidential data was stolen, not by any hacker, but by an employee, is a nightmare scenario that no one wants to face.

But it's also a risk that's very real. The recent arrest of a former NSA contractor suspected of stealing classified government files is just the latest high-profile example, and security experts say all companies need to be on guard against potential insider threats.

How serious is the threat?

It's not every day that thieving employees take to the digital black market to sell their company's sensitive information, but it does happen, and incidents have been occurring more frequently, said Andrei Barysevich, a director at security firm Flashpoint.

Flashpoint specializes in investigating marketplaces on the Dark Web for possible sales involving private company data. In one such case, it identified an employee of a major software company attempting to sell valuable source code for about $15,000.

Flashpoint has also detected other incidents of insiders trying to sell information from financial companies, healthcare providers and law firms, all of which hold valuable data such as bank account numbers, patient information and upcoming merger and acquisition deals.

In many of those cases, it appears the insider had access to sensitive data that no one at their companies bothered to monitor, Barysevich said. That's a serious problem, and he advises companies to segregate all valuable data away from employees who don't have a reason to use it. He also says they should create a culture where employees are aware of the insider threat.

Not all are malicious

Data protection company Bitglass has also been studying the insider threat. In a report published last month, it found that one-third of organizations surveyed had experienced an insider attack within the past year in which data was leaked.

However, malicious insiders weren't the only ones to blame. Careless employees caused some of the leaks. "Inadvertent leakage is also a big problem," said Salim Hafid, product manager for Bitglass. 

Cloud-based applications and bring-your-own-device policies have only made it easier to accidentally share or publish confidential data, he said. As a result, more corporate data is getting out of company networks and into personal smartphones and file-sharing systems.  

"A huge number of organizations that have cloud applications deployed have no means to identify these careless activities and no way to mitigate the threat," Hafid said. Companies like Bitglass sell services to fill those gaps.

Security vs. Privacy

To solve the problem, security firms are also coming up with products that can monitor access to a company's most sensitive files. The European company Balabit has created Blindspotter, which is designed to detect any unusual employee activity on corporate systems.

It does this by looking at where the employee is accessing the data, what applications are being opened and even mouse movement and keyboard strokes, said Balabit CTO Balázs Scheidler. The Blindspotter software can then score what activity looks suspicious and even react by terminating an employee's corporate connection.

"We get a very intimate insight into what you are doing," Scheilder said. "Traditional tools aren't capable of looking at this traffic."

That insight may not be to everyone's liking. With real-time monitoring can come concerns about violating employee privacy.

"It's important for the companies to be transparent and communicate to those who are being monitored why this is happening," Scheilder said. The monitoring doesn't have to involve all employees. It can focus on those with high-level access, such as system administrators, who could be the target of hackers or insider threats trying to steal their login credentials.  

"The kind of damage that can happen if your account is stolen ... can be communicated very clearly," he said.

Maintaining the right approach

Companies that do suspect an insider threat should contact the professionals, said Eric O'Neill, national security strategist for security firm Carbon Black.

"You shouldn't do it alone," he said. "You don't want to corrupt the investigation. These things can get touchy."

That can be especially true when malicious employees are trying to cover their tracks. Evidence needs to be found and preserved to help determine the full extent of what may have been stolen, O'Neill said.

It's also important not to go too far in catching insider threats. "Certain procedures can make employees feel like they are working in a police state," he said.

However, O'Neill encourages companies to take insider threats seriously. "Many companies and government agencies still have a blind spot with this problem," he said. "It's one of the most difficult issues facing security."

Computerworld

 

« Stolen NSA Hacking Tools For Sale In Bizarre Auction
Pentagon Creates New 5,000 Strong Cyber Force »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Help Net Security

Help Net Security

Help Net Security has been a prime resource for information security news and insight since 1998.

Australian Signals Directorate (ASD)

Australian Signals Directorate (ASD)

The Australian Signals Directorate is an intelligence agency in the Australian Government Department of Defence.

TrustArc

TrustArc

TrustArc provide privacy compliance and risk management with integrated technology, consulting and TRUSTe certification solutions – addressing all phases of privacy program management.

Logic Supply

Logic Supply

Logic Supply is a global industrial PC company focused on hardware for the IoT edge. We design highly-configurable computers engineered for reliability.

Bessemer Venture Partners (BVP)

Bessemer Venture Partners (BVP)

Bessemer Venture Partners was born from innovations that literally forged modern building and manufacturing. Today, our team of investors works with people who want to create revolutions of their own.

Reed

Reed

reed.co.uk is a leading job site in the UK, providing a full online service for anyone looking for a new job.

Right-Hand Cybersecurity

Right-Hand Cybersecurity

Right-Hand Cybersecurity empowers businesses to monitor, measure and mitigate employee induced cyber risks in real-time.

Jacobs

Jacobs

Jacobs is at the forefront of the most important security issues today. We are inspired to be the best and deliver innovative, mission-focused outcomes that matter to our clients.

Activu

Activu

Activu makes any information visible, collaborative, and proactive for people tasked with monitoring critical operations including network security.

Thistle Technologies

Thistle Technologies

Thistle Technologies is building tools that help connected device manufacturers build security resiliency into devices.

CyberAcuView

CyberAcuView

CyberAcuView is a company dedicated to enhancing cyber risk mitigation efforts across the insurance industry.

Swiss Cyber Forum (SCF)

Swiss Cyber Forum (SCF)

The Swiss Cyber Forum (SCF) builds competences and helps its members to mitigate the cyber risks associated with digitalisation.

Policy Monitor

Policy Monitor

Policy Monitor is a cyber security company founded by experts with extensive experience in operational and risk management.

Jera IT

Jera IT

Jera IT provide fully managed IT support, cybersecurity services, telecoms systems, and IT strategy consultancy to businesses based in Aberdeen and the surrounding area.

DIGISOC

DIGISOC

DIGISOC, a leader in Latin America in Cybersecurity solutions, combines machine learning with human intelligence to be effective in detecting cyber threats.

Cytex

Cytex

Cytex is the All-in-One solution for SMB data protection & compliance needs.